Hello,
I have an urgent security request. Our shop contains malicious code that is only present in cached files.
At the end of those cached files there's some encrypted javacript code added which adds a reference to an IP adress - at least that's why understand. It's explained here: http://www.stopthehacker.com/2011/12/08/rokbox-js-infections/
Of course I cleaned/deleted all affected files and changed DB, FTP and Admin Logins. However new cached files are being created in the theme's cache directory which contain the mentioned code.
Where can I check how the cached files are created in Prestashop? I suspect this code is added automatically when a JS file is copied into the cache.
Or even better: Has anyone come across this type of malware and knows how to fix it?
Thanks for your help.